Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Mageia: 2020-0313 Critical: Php-PhpMailer Insufficient Escaping Issue

mageia
Calendar Grey August 1, 2020
Dist Mageia Esm H88
Mageia security advisory MGASA-2020-0313 resolves an issue with php-phpmailer regarding inadequate escaping of filenames for attachments.
Fix insufficient output escaping bug in file attachment names (CVE-2020-13625)

Summary

Fix insufficient output escaping bug in file attachment names (CVE-2020-13625).

References

- https://bugs.mageia.org/show_bug.cgi?id=26760

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OBRDMEV3CB44CAAF5BOHFNV23JVRO6PZ/

- https://github.com/advisories/GHSA-f7hx-fqxw-rvvj

- https://www.cve.org/CVERecord?id=CVE-2020-13625

Resolution

SRPMS

- 7/core/php-phpmailer-6.1.6-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 01 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0313.html
Type: security
CVE: CVE-2020-13625

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here